Web3 Loses $763.9M in Q2 as Key Management Fails

Threat actors stole $763.9 million across 67 Web3 incidents in Q2 2026; most losses came from compromised keys, signer devices and infrastructure despite audits.

Threat actors extracted $763.9 million from Web3 projects in the second quarter of 2026 across 67 incidents. Hacken’s quarterly report attributes $674.5 million, or 88.3% of the total, to operational and key-management failures rather than flaws in smart contract code.

Smart contract bugs were the most common incident type, occurring in 44 of the 67 cases, but they accounted for about 11% of funds lost. Two incidents attributed to North Korean threat actors represented roughly 75.5% of the quarter’s total value stolen. Fourteen protocols that had undergone audits were breached during the quarter.

The report found only 9% of tracked projects operate continuous monitoring and just 4% combine audits, bug bounties and live monitoring. It also shows a gap between the scope of typical audits and the systems attackers targeted.

Security practitioners note audits review a specific codebase at a point in time and do not cover signer devices, cloud configurations, operational permissions, deployed bytecode changes, later upgrades, third-party dependencies or callable legacy contracts. Leo Fan, founder of Cysic, warned audits are scoped assessments that do not guarantee protection of the systems that control keys and transactions. Eric Swartz, founding general partner and general counsel at Panther Hollow Ventures, added that a snapshot review cannot account for later operational changes or new attack methods.

Attackers are focusing on the off-chain control plane. Observed targets include signer devices, key generation and rotation processes, cloud identities, CI/CD pipelines, backend services, bridge validators and emergency admin paths. Jerald David, CEO of Lynq, observed that cloud providers secure underlying infrastructure but do not manage application configurations, credential practices or access policies for teams. Samuel Videau, CTO at Genius, pointed to cases where over‑permissive service accounts and CI/CD pipelines undermined multisignature protections and where deprecated contracts retaining admin rights were used to drain funds.

Institutional evaluators are changing due diligence to emphasize continuous monitoring, privileged-access governance, clear privilege maps and multiparty authorization for any action that can move assets or change safeguards. Jerald David looks first at operational maturity and expects teams to explain how capital moves through their systems and where controls sit. Himanshu Sahay, CTO and co‑founder of Arch, noted that audits remain part of security but cannot replace ongoing operational controls.

Experts predict the pattern will continue into the second half of 2026, with attackers favoring social engineering, credential theft, signer compromise, cloud or CI/CD intrusions and attacks on off‑chain validator infrastructure. Samuel Videau urged teams to align security spending with the areas where losses have occurred, given that nearly 90% of stolen funds moved through keys and infrastructure.

Industry participants identified wider adoption of live monitoring, stronger key‑management discipline, multiparty controls and transparent operational governance as measures projects are prioritizing to address the gap between audit scope and operational risk.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author